Anthropic CEO Dario Amodei published a blog post on July 27 that tries to cut through a week of confusion. The post is a direct response to reports that some US officials are considering banning US companies from using Chinese open-weights models, and to an industry open letter supporting open-weights models that some critics claimed Anthropic opposed.
Amodei states plainly: “Anthropic has never advocated for a ban on open-weights models.” He calls open-weights models that lack dangerous capabilities “a public good.” The post is notable for what it accepts and what it rejects. It accepts the premise that open-weights models pose unique safety risks. It rejects the idea that banning US businesses from using them is the right response.
The core of the argument rests on two nightmare scenarios Amodei laid out six months ago in an essay called The Adolescence of Technology. The primary concern is that authoritarian governments, especially China, build AI models more powerful than those in the US and use them for military superiority or repression. The secondary concern is that powerful models get misused for cyberattacks or biological attacks, with open-weights models presenting a higher risk because guardrails are hard to apply and weights cannot be withdrawn once released.
Amodei argues that banning US businesses from using Chinese open-weights models addresses neither concern. Bad actors are not legitimate US businesses. The most dangerous model might be one trained in secret and handed directly to the People’s Liberation Army. “It is irrelevant whether these models are released with open weights,” he writes, “and certainly irrelevant whether they are used by US businesses.”
Instead, Amodei endorses three measures. First, the US should not sell powerful chips or chipmaking equipment to China, and should crack down on smuggling. China’s limited domestic production capacity means it cannot build more powerful models than the US without US chips, due to scaling laws. This is the most direct way to block the primary threat.
Second, the US should crack down on industrial-scale distillation operations. Distillation is more compute-efficient than training from scratch. It allows China to build much better models than its chip count would ordinarily enable, partially evading chip bans. Amodei says distillation does not let China obtain equivalent or superior capabilities, but it can bring the Chinese frontier within a few months of the US frontier. He notes that many companies running these operations release open-weights models, but the open weights are “far less relevant” than the fact that the operations are backed by an authoritarian state.
Third, all sufficiently capable models, open and closed, should go through mandatory safety testing. Amodei says this is close to a consensus. He points to the Trump administration moving in this direction and to recent industry proposals that would apply testing to the most capable models regardless of country of origin or whether they are open or closed. Less capable models from startups and academia would be exempted entirely. Testing would need to be global, which means even China would need to participate. Amodei thinks limited cooperation on preventing AI biological weapons may be possible because it is in China’s interest too.
The post also addresses the open letter that many tech companies signed. Amodei agrees with much of it: open weights expand access to the AI economy, strengthen competition for some use cases, and give customers greater control. But he disagrees with the letter’s assertion that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities helps defenders more than attackers. He writes that the opposite seems at least as likely, citing biology as a domain with strong attacker-defender asymmetry. A sufficiently capable model might weaponize pandemic-level viruses quickly, while defense is a multi-year task.
This is a carefully calibrated position. It puts Anthropic on the side of open-weights models as a category while endorsing the policy tools that would constrain them indirectly. The chip export controls and distillation crackdown are the teeth. The mandatory safety testing is the framework. The blanket ban is the thing Amodei says he never wanted.
The timing matters. The debate over Chinese open-weights models has intensified as models like DeepSeek’s V3 and Qwen have demonstrated capabilities that rival US frontier models. US officials have floated measures that would effectively wall off the US AI ecosystem from Chinese models. The industry open letter pushed back hard. Amodei’s post is an attempt to occupy the middle ground: not protectionist, not laissez-faire, but targeted at the supply chain and the testing regime.
What is missing from the post is detail on how mandatory safety testing would work in practice. Who sets the threshold for “sufficiently capable”? Who conducts the tests? How does enforcement work when a model is released from a jurisdiction that does not participate? Amodei acknowledges that testing would need to be global and that Chinese cooperation is necessary, but he does not say what happens if that cooperation does not materialize.
The post also leaves open the question of whether open-weights models from US companies should face the same testing requirements as those from China. Amodei says the testing should apply to “all sufficiently capable models, open and closed,” regardless of country of origin. That is a significant concession to the safety-first camp. It means Meta’s Llama 4, if it crosses the capability threshold, would face the same pre-release testing as a Chinese model.
Anthropic’s business interest is clear. The company sells access to closed models through its API and consumer products. It does not release open-weights models. A world with mandatory safety testing for capable models raises the bar for everyone, but it raises it higher for open-weights releases that cannot be patched or monitored after the fact. Amodei denies that protecting Anthropic’s business is his goal. The policy measures he endorses would nonetheless shape the competitive landscape in ways that favor closed-model providers.
The debate is not over. The open letter signatories have their answer from Anthropic. The question now is whether the Trump administration and Congress will adopt the targeted measures Amodei advocates, or whether the pressure for a broader ban will win out. The chip export controls are already in place. The distillation crackdown and mandatory safety testing are not.